Executive brief
stack_collections is a Rust library providing stack-allocated vector types. A double-free vulnerability in the StackVec::retain method can occur when filtering elements if the filter predicate or a dropped element's cleanup code panics, potentially corrupting memory and enabling denial of service or code execution in affected applications.
Technical details
The vulnerability is a double-free in StackVec::retain caused by unsafe unwinding semantics: self.len is only updated after the entire filter loop completes, so if unwinding occurs mid-loop, the element count remains at its pre-retain value. StackVec's Drop implementation then revisits and double-drops the same slot. This affects only builds with panic unwinding enabled; panic=abort and no_std builds are unaffected. The fix in version 0.3.3 uses an unwind-safe guard similar to std::vec::Vec::retain.
Affected products
- stack_collections stack_collections 0.3.0 to 0.3.2
Timeline
- 2026-09-22: disclosed
- 2026-09-22: patched: Fixed in version 0.3.3